RESTEasy: creation of insecure temp files
Published Feb 17, 2023
5.5
MEDIUMCVSS 3.1
EPSS 0.26%
Description
In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
Affected products
- Vendor n/a Product RESTEasy Defaultn/a
- Version Fixed in RESTEasy 4.7.8.FinalStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | RESTEasy | n/a |
|
Configuration 1
Configuration 2
- n/a
- n/a
- n/a
- n/a
No data.
AMQ Broker 7.10.3
resteasy
Fixed · RHSA-2023:3185
MTA-6.1-RHEL-8
mta/mta-hub-rhel8:6.1.4-2
Fixed · RHSA-2023:6305
MTA-6.1-RHEL-8
mta/mta-operator-bundle:6.1.4-3
Fixed · RHSA-2023:6305
MTA-6.1-RHEL-8
mta/mta-pathfinder-rhel8:6.1.4-1
Fixed · RHSA-2023:6305
MTA-6.1-RHEL-8
mta/mta-rhel8-operator:6.1.4-3
Fixed · RHSA-2023:6305
MTA-6.1-RHEL-8
mta/mta-ui-rhel8:6.1.4-2
Fixed · RHSA-2023:6305
MTA-6.1-RHEL-8
mta/mta-windup-addon-rhel8:6.1.4-2
Fixed · RHSA-2023:6305
RHEL-8 based Middleware Containers
rh-sso-7/sso76-openshift-rhel8:7.6-22
Fixed · RHSA-2023:2710
RHPAM 7.13.4 async
resteasy
Fixed · RHSA-2023:4983
RHPAM 7.13.5 async
resteasy
Fixed · RHSA-2024:1353
Red Hat AMQ Streams 2.5.0
n/a
Fixed · RHSA-2023:5165
Red Hat JBoss Enterprise Application Platform 7
resteasy
Fixed · RHSA-2023:1516
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2023:1513
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2023:1514
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el7eap
Fixed · RHSA-2023:1512
Red Hat Single Sign-On 7
resteasy
Fixed · RHSA-2023:2713
Red Hat Single Sign-On 7.6 for RHEL 7
rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el7sso
Fixed · RHSA-2023:2705
Red Hat Single Sign-On 7.6 for RHEL 8
rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el8sso
Fixed · RHSA-2023:2706
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el9sso
Fixed · RHSA-2023:2707
A-MQ Clients 2
resteasy
Fix deferred
Migration Toolkit for Runtimes
org.keycloak-keycloak-parent
Affected
Red Hat A-MQ Online
resteasy
Fix deferred
Red Hat Data Grid 8
resteasy
Not affected
Red Hat Enterprise Linux 8
resteasy
Fix deferred
Red Hat Enterprise Linux 9
resteasy
Fix deferred
Red Hat Fuse 7
resteasy
Fix deferred
Red Hat Integration Camel K 1
resteasy
Not affected
Red Hat JBoss Data Grid 7
resteasy
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
resteasy
Out of support scope
Red Hat JBoss Enterprise Application Platform Expansion Pack
resteasy
Affected
Red Hat build of Apicurio Registry 2
resteasy
Affected
Red Hat build of Quarkus
resteasy-core
Not affected
Red Hat support for Spring Boot
resteasy
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| AMQ Broker 7.10.3 | resteasy | Fixed | RHSA-2023:3185 |
| MTA-6.1-RHEL-8 | mta/mta-hub-rhel8:6.1.4-2 | Fixed | RHSA-2023:6305 |
| MTA-6.1-RHEL-8 | mta/mta-operator-bundle:6.1.4-3 | Fixed | RHSA-2023:6305 |
| MTA-6.1-RHEL-8 | mta/mta-pathfinder-rhel8:6.1.4-1 | Fixed | RHSA-2023:6305 |
| MTA-6.1-RHEL-8 | mta/mta-rhel8-operator:6.1.4-3 | Fixed | RHSA-2023:6305 |
| MTA-6.1-RHEL-8 | mta/mta-ui-rhel8:6.1.4-2 | Fixed | RHSA-2023:6305 |
| MTA-6.1-RHEL-8 | mta/mta-windup-addon-rhel8:6.1.4-2 | Fixed | RHSA-2023:6305 |
| RHEL-8 based Middleware Containers | rh-sso-7/sso76-openshift-rhel8:7.6-22 | Fixed | RHSA-2023:2710 |
| RHPAM 7.13.4 async | resteasy | Fixed | RHSA-2023:4983 |
| RHPAM 7.13.5 async | resteasy | Fixed | RHSA-2024:1353 |
| Red Hat AMQ Streams 2.5.0 | n/a | Fixed | RHSA-2023:5165 |
| Red Hat JBoss Enterprise Application Platform 7 | resteasy | Fixed | RHSA-2023:1516 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2023:1513 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2023:1514 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el7eap | Fixed | RHSA-2023:1512 |
| Red Hat Single Sign-On 7 | resteasy | Fixed | RHSA-2023:2713 |
| Red Hat Single Sign-On 7.6 for RHEL 7 | rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el7sso | Fixed | RHSA-2023:2705 |
| Red Hat Single Sign-On 7.6 for RHEL 8 | rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el8sso | Fixed | RHSA-2023:2706 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el9sso | Fixed | RHSA-2023:2707 |
| A-MQ Clients 2 | resteasy | Fix deferred | n/a |
| Migration Toolkit for Runtimes | org.keycloak-keycloak-parent | Affected | n/a |
| Red Hat A-MQ Online | resteasy | Fix deferred | n/a |
| Red Hat Data Grid 8 | resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 8 | resteasy | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | resteasy | Fix deferred | n/a |
| Red Hat Fuse 7 | resteasy | Fix deferred | n/a |
| Red Hat Integration Camel K 1 | resteasy | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | resteasy | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | resteasy | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | resteasy | Affected | n/a |
| Red Hat build of Apicurio Registry 2 | resteasy | Affected | n/a |
| Red Hat build of Quarkus | resteasy-core | Not affected | n/a |
| Red Hat support for Spring Boot | resteasy | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Mar 18, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2023–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.26% (0.00261) | 16.29th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.82% (0.00819) | 52.24th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.04% (0.00037) | 7.80th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 18, 2023 | 0.89% (0.00885) | 27.67th | v2 (v2022.01.01) |
References (17)
- https://access.redhat.com/security/cve/CVE-2023-0482 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2166004 Issue Tracking
- https://github.com/advisories/GHSA-2c6g-pfx3-w7h8 Advisory
- https://github.com/orgs/resteasy/discussions/3415
- https://github.com/orgs/resteasy/discussions/3504
- https://github.com/orgs/resteasy/discussions/3506
- https://github.com/resteasy/resteasy/pull/3409
- https://github.com/resteasy/resteasy/pull/3409/commits/807d7456f2137cde8ef7c316707211bf4e542d56 Patch
- https://github.com/resteasy/resteasy/pull/3410
- https://github.com/resteasy/resteasy/pull/3412
- https://github.com/resteasy/resteasy/pull/3413
- https://github.com/resteasy/resteasy/pull/3423
- https://github.com/resteasy/resteasy/security/advisories/GHSA-2c6g-pfx3-w7h8
- https://issues.redhat.com/browse/RESTEASY-3286
- https://nvd.nist.gov/vuln/detail/CVE-2023-0482
- https://security.netapp.com/advisory/ntap-20230427-0001 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-0482
Change history (0)
No recorded changes yet.